<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Offgrid Security Research</title>
    <link>https://www.offgridsec.com/case-studies.html</link>
    <description>Original vulnerability research and practical application-security guidance from Offgrid Security.</description>
    <language>en</language>
    <lastBuildDate>Wed, 29 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>OpenAI Open-Sourced Codex Security. Here's How It Compares to Kira.</title>
      <link>https://www.offgridsec.com/blog-kira-vs-codex-security.html</link>
      <guid isPermaLink="true">https://www.offgridsec.com/blog-kira-vs-codex-security.html</guid>
      <description>OpenAI released Codex Security, an LLM-only application security agent. We studied the codebase. Here's what we found and why Kira chose a different architecture.</description>
      <category>Blog</category>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kira Found SSRF in Ghost's Webhook Delivery: The Fix Was Already Written</title>
      <link>https://www.offgridsec.com/blog-ghost-cve-2026-53945.html</link>
      <guid isPermaLink="true">https://www.offgridsec.com/blog-ghost-cve-2026-53945.html</guid>
      <description>Ghost maintained a hardened SSRF-safe HTTP library and used it everywhere, except webhooks. One line away from safe. A deep dive into CVE-2026-53945.</description>
      <category>Blog</category>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kira Found a CVSS 10.0 Full Compromise in Hoppscotch</title>
      <link>https://www.offgridsec.com/blog-hoppscotch-cve-2026-50160.html</link>
      <guid isPermaLink="true">https://www.offgridsec.com/blog-hoppscotch-cve-2026-50160.html</guid>
      <description>One unauthenticated HTTP request grants full server compromise via JWT secret injection. A deep dive into CVE-2026-50160, four chained weaknesses, and what it means for your NestJS stack.</description>
      <category>Blog</category>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Hoppscotch CVE-2026-50160: Unauthenticated Server Takeover</title>
      <link>https://www.offgridsec.com/case-studies/hoppscotch-cve-2026-50160/</link>
      <guid isPermaLink="true">https://www.offgridsec.com/case-studies/hoppscotch-cve-2026-50160/</guid>
      <description>Technical report on CVE-2026-50160, a CVSS 10.0 mass-assignment vulnerability in Hoppscotch that enabled JWT secret injection and full server compromise.</description>
      <category>Research report</category>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cognithor API Key Exposure: Unauthenticated Secret Disclosure</title>
      <link>https://www.offgridsec.com/case-studies/cognithor-api-key-exposure/</link>
      <guid isPermaLink="true">https://www.offgridsec.com/case-studies/cognithor-api-key-exposure/</guid>
      <description>Technical report on an unauthenticated Cognithor endpoint that exposed configured provider API keys, plus the verified remediation in v0.78.2.</description>
      <category>Research report</category>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Ghost CVE-2026-53945: Webhook SSRF Vulnerability</title>
      <link>https://www.offgridsec.com/case-studies/ghost-cve-2026-53945/</link>
      <guid isPermaLink="true">https://www.offgridsec.com/case-studies/ghost-cve-2026-53945/</guid>
      <description>Technical report on CVE-2026-53945, an SSRF flaw in Ghost webhook delivery that could reach internal services and cloud metadata endpoints.</description>
      <category>Research report</category>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
